← Back

Ubuntu Linux

ubuntu_linux

Vendor: Canonical • 4,120 CVEs

CVEs (4,120)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Canonical
Gnome
2Gnome Remote Desktop
Ubuntu Linux
Jun 17, 2026
Jan 31, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
13Almalinux
AmazonApple+10 more
53500f Firmware
8300 Firmware8700 Firmware+50 more
Jun 17, 2026
Jul 1, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able t...Show more
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.Show less
1Canonical
2Snapd
Ubuntu Linux
Jun 17, 2026
Jun 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snap...Show more
When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended.Show less
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Apport does not disable python crash handler before entering chroot
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
is_closing_session() allows users to consume RAM in the Apport process
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
is_closing_session() allows users to create arbitrary tcp dbus connections
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
is_closing_session() allows users to fill up apport.log
2Apport Project
Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
1Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Apport can be tricked into connecting to arbitrary sockets as the root user
1Canonical
2Apport
Ubuntu Linux
Jun 17, 2026
Jun 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Jun 17, 2026
Jan 8, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15...Show more
The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15c7691e9b13cbe9bf6c65c365350e056067.Show less
4Canonical
FedoraprojectLinux+1 more
4Enterprise Linux
FedoraLinux Kernel+1 more
Jun 17, 2026
Jan 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execut...Show more
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.Show less
1Canonical
2Snapd
Ubuntu Linux
Jun 17, 2026
Jan 8, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
Race condition in snap-confine's must_mkdir_and_open_with_perms()
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Jun 17, 2026
Jan 8, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
io_uring UAF, Unix SCM garbage collection
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Jun 17, 2026
Jan 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Jun 17, 2026
Jan 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Jun 17, 2026
Jan 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.
1Canonical
1Ubuntu Linux
Jun 17, 2026
Dec 12, 2023
N/A· v4
6.4 MEDIUM· v3
N/A· v2
A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.
5Apple
CanonicalDebian+2 more
7Android
Debian LinuxFedora+4 more
Jun 17, 2026
Dec 8, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages w...Show more
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.Show less